Loading [MathJax]/extensions/MathMenu.js
Proposed Framework for Network Lateral Movement Detection Based On User Risk Scoring in SIEM | IEEE Conference Publication | IEEE Xplore

Proposed Framework for Network Lateral Movement Detection Based On User Risk Scoring in SIEM


Abstract:

Network lateral movement or simply called lateral movement is the latest techniques used by cyber attackers to progressively move through a network while they search and ...Show More

Abstract:

Network lateral movement or simply called lateral movement is the latest techniques used by cyber attackers to progressively move through a network while they search and gathered key information data to be used for their cyber-attacks. The best defense mechanism to neutralize this attack method is by correlating data from various sources to reveal the structure and perpetual attack patterns. In this paper, we proposed a framework for lateral movement detection based on pattern risk scoring. Users are segmented into clusters and each cluster were assigned a profile. The user who breaches the profile is given a score rating subject to the relationship and accessing patterns. The user with high score is quarantined while low score user is monitored. Any outgoing traffic from the users is temporarily hold whilst the server verifies the destination address. The proposed framework in this paper can be integrated into the existing network security devices such as next-generation firewall, Advanced Persistent Threat (APT) or Security Information and Event Management (SIEM) to improve the lateral movement detection.
Date of Conference: 24-26 July 2018
Date Added to IEEE Xplore: 20 December 2018
ISBN Information:
Conference Location: Kuching, Malaysia

Contact IEEE to Subscribe

References

References is not available for this document.